Browse categories
AIAltcoinsAnalysisBitcoinBlockchainCryptoDeFiEthereumExchangesFundingGoldInstitutionalLayer 2MacroMarketsMemecoinsMiningNewsOn-ChainPaymentsRegulationRWASecurityStablecoinsTradFi
BTC$85,677.00▲ 0.91%
ETH$2,704.35▲ 0.28%
BNB$790.84▲ 0.50%
SOL$120.39▼ 0.49%
XRP$1.50▲ 0.83%
ADA$0.2687▲ 9.89%
BTC$85,677.00▲ 0.91%
ETH$2,704.35▲ 0.28%
BNB$790.84▲ 0.50%
SOL$120.39▼ 0.49%
XRP$1.50▲ 0.83%
ADA$0.2687▲ 9.89%

Bitcoin Core Adds Safeguard for Partially Signed Transactions

Bitcoin Core has introduced a new security measure to prevent signatures in partially signed transactions from being reused if the intended recipient is altered.

Bitcoin Core has implemented a new safeguard designed to ensure that transaction signatures are strictly bound to the payment destination approved by the user. The update, which was merged into the project's master development branch on Sept. 25, addresses a specific vulnerability within partially signed Bitcoin transactions, or PSBTs.

The issue, highlighted by Bitcoin Optech on Oct. 2, does not compromise a user's private keys. Instead, it involves a risk where a signature could remain valid even if the transaction recipient is changed under certain conditions. This vulnerability centers on SIGHASH_SINGLE, a signing mode intended to commit an input to a corresponding output.

When using SIGHASH_SINGLE, if the transaction lacks an output at the expected position, the protection mechanism can fail. For legacy inputs, this can result in a signature over a fixed hash value that might be reused against other unspent outputs controlled by the same key. While SegWit v0 transactions maintain stronger protections regarding the coin and amount, the destination output can still remain unbound.

This creates a potential authorization issue for wallets and signing devices, as software could display one payment destination to a user while generating a signature that does not cryptographically guarantee that the recipient remains unchanged. Bitcoin Core previously rejected this edge case through its raw-transaction signing interface, but the PSBT path remained susceptible.

The new code integrates a check directly into the shared signature-creation logic. This prevents affected legacy and SegWit v0 inputs from being signed while allowing other valid inputs within the same PSBT to be processed. This change reinforces the requirement that a cryptographic signature must commit to the specific transaction details authorized by the user.

As of Oct. 4, the fix is only available in the Bitcoin Core development branch, with no confirmed production release or backport identified. Consequently, wallet providers and hardware-signing integrations are encouraged to review their own handling of SIGHASH_SINGLE requests to ensure they are enforcing the necessary protections independently.

Crypto Research
@cryptoresearch
55.2K members · Free real-time crypto news and price alerts, the moment they break.
Join
989,566
Total members across the Channels
@ChartsSignalsTrading
116K members
Join
@OnlyFinance_Pro
90.4K members
Join
@Nakamoto_Signals
76.7K members
Join
@BlackBlockMarkets
74.7K members
Join
@Bitunix_Trades
70.0K members
Join
View all channels →